Monitoring Splunk

monitoring log truncated

rjfv8205
Path Finder

We have a service where logs are truncated. Example, we have hola.log that fridays copy all content to new file hola20190306.log and hola.log is empty.

My question, if universal forwarder monitoring hola.log, send info from begin or from position of the last event before truncated? Lost some events?

Sorry my english is not very good

Thank you in advance

Tags (1)
0 Karma

jnahuelperez35
Path Finder

It always send information from the last line that was generated.
If universal forwarder is monitoring the file named "hola.log" will monitor every line that was generated, after being empty or at leats all the lines goes to new "hola.log"

EDiT: you will never lost logs. i leave you this link that can help you to understand best practices about log rotation https://answers.splunk.com/answers/577144/about-log-rotation-best-practices.html

Let me know if i answer your question.

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...